Re: Unofficial PEAR meeting summary
| From: | Cipriano Groenendal | Date: | Thu, 06 May 2004 20:34:33 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28908@lists.php.net to get a copy of this message | ||
> On Thu May 06, 2004 at 02:3008PM -0500, Paul M Jones wrote:
> > Is the PEAR credentials interface really in the open like that? Should
> > we be passing credentials in the clear? Perhaps I am too paranoid...
> Pear.php.net's authentication interface cannot be used via any sort of
> network connection. And I don't think that this will change any time
> soon.
Martin.
If you look at Auth/Container/PEAR.php, you'll see that the Auth package
uses an RPC call to get userinfo. Within taht is the md5sum of the pass,
which is compared to a locally md5'd password string. Wether this is by
design, or a bug, in cases like this it's quite cool :)
However, we are not passing anything in the open, except for perhaps and
md5sum of the password. This could be considered
secure by most people ,
unless you're really paranoid :)
Cipri